pub struct SmApiClient { /* private fields */ }Expand description
SM API client. Stateless until SmApiClient::login establishes a session.
Implementations§
Source§impl SmApiClient
impl SmApiClient
Sourcepub fn new(base_url: Url, flow: LoginFlow) -> Self
pub fn new(base_url: Url, flow: LoginFlow) -> Self
Build a client for the SM API base (e.g. https://<sm-api-host>/api/v1).
Sourcepub fn with_http_client(base_url: Url, http: Client, flow: LoginFlow) -> Self
pub fn with_http_client(base_url: Url, http: Client, flow: LoginFlow) -> Self
Build with a caller-provided reqwest client (tests / shared client).
Sourcepub async fn login(
&mut self,
access_token: &str,
sm_id_token: Option<&str>,
) -> Result<(), AuthError>
pub async fn login( &mut self, access_token: &str, sm_id_token: Option<&str>, ) -> Result<(), AuthError>
Establish a session: POST /login with the Okta access token, then fetch the CSRF
token. Pass sm_id_token only for SSO logins (omit for Google/GitHub).
Returns AuthError::MfaRequired when SM challenges the login; call
SmApiClient::complete_mfa on this same client to finish it.
Sourcepub async fn complete_mfa(
&mut self,
access_token: &str,
sm_id_token: Option<&str>,
code: &str,
) -> Result<(), AuthError>
pub async fn complete_mfa( &mut self, access_token: &str, sm_id_token: Option<&str>, code: &str, ) -> Result<(), AuthError>
Finish an MFA-challenged login with a TOTP code, reusing the challenged session.
Errors with AuthError::Protocol if no challenge is outstanding — submitting a code on a
fresh session cannot work, because SM verifies it against challenge state held in the
session it issued.
Sourcepub async fn fetch_current_user(&self) -> Result<SmUser, AuthError>
pub async fn fetch_current_user(&self) -> Result<SmUser, AuthError>
GET /users/me.
Sourcepub async fn ensure_capi_enabled(&self) -> Result<bool, AuthError>
pub async fn ensure_capi_enabled(&self) -> Result<bool, AuthError>
POST /accounts/cloud-api/cloudApiAccessKey — enable programmatic access. Idempotent:
a 400 account_api_key_already_exists is treated as success.
Returns whether this call is what switched programmatic access on, so a caller can say so
rather than enabling an account-wide setting silently.
Sourcepub async fn mint_capi_key(
&self,
name: &str,
user_account: u64,
) -> Result<CapiKey, AuthError>
pub async fn mint_capi_key( &self, name: &str, user_account: u64, ) -> Result<CapiKey, AuthError>
POST /accounts/cloud-api/cloudApiKeys — mint a named user secret key.
Sourcepub async fn fetch_capi_keys(&self) -> Result<Vec<String>, AuthError>
pub async fn fetch_capi_keys(&self) -> Result<Vec<String>, AuthError>
GET /accounts/cloud-api/cloudApiKeys — list existing CAPI key names. Best-effort: used
only to warn about redisctl-* key sprawl at login, so tolerant of response shape.
Sourcepub async fn fetch_capi_key_entries(
&self,
) -> Result<Vec<(u64, String)>, AuthError>
pub async fn fetch_capi_key_entries( &self, ) -> Result<Vec<(u64, String)>, AuthError>
GET /accounts/cloud-api/cloudApiKeys, as (id, name) pairs.
Sourcepub async fn delete_capi_key(&self, id: u64) -> Result<(), AuthError>
pub async fn delete_capi_key(&self, id: u64) -> Result<(), AuthError>
DELETE /accounts/cloud-api/cloudApiKeys/{id} — revoke a minted key server-side.
Sourcepub async fn set_current_account(
&self,
account_id: u64,
) -> Result<(), AuthError>
pub async fn set_current_account( &self, account_id: u64, ) -> Result<(), AuthError>
Rebind the session to account_id (POST /accounts/setcurrent/{id}).
Every CAPI call resolves the account from the session — createApiSecretKey uses the
session’s userAccountId — so this must happen before enabling access or minting, or the
key lands on the previous account. Annotated LEGACY_ONLY server-side, which the JSESSIONID
established by SmApiClient::login satisfies.